
Some users of Meta AI may unknowingly have their search prompts and results made public, as their interactions with the AI tool are posted on a public feed. This includes searches that could be easily traced to their social media accounts.
An internet security expert has described this as a "huge user experience and security issue", as some posts can be directly linked to users' identities. As a result, individuals may inadvertently expose personal queries, such as requests for AI to generate revealing characters or assist with cheating on exams.
Meta claims that chats are private by default, but users can choose to make their posts public and later retract them. A warning message appears before a post is shared, notifying users that "prompts you post are public and visible to everyone […] Avoid sharing personal or sensitive information". However, it remains unclear whether users fully realise that their searches are being added to a public ‘Discover’ feed on the Meta AI app and website. It may also be connected to their other social accounts through their usernames and profile pictures.
The BBC discovered several instances where users uploaded images of school or university exam questions, seeking answers from Meta AI. Other conversations included personal topics, such as gender identity exploration and searches for scantily-clad characters.
Meta AI, launched earlier this year, is accessible through Facebook, Instagram and WhatsApp, as well as a standalone product with a public ‘Discover’ feed. Users can adjust their privacy settings to make their searches private.
In a press release, Meta reassured users they were "in control" of what was shared, stating that nothing would be posted unless they chose to do so. However, cybersecurity expert Rachel Tobac pointed out that when users' expectations do not match how the tool functions, it leads to significant security risks. She emphasised that users do not expect their AI chatbot interactions to be shared publicly, resulting in the inadvertent exposure of sensitive information tied to their identity.